Google has released its latest Chrome 155 update, targeting a significant number of security vulnerabilities, with a total of 247 flaws addressed. This update, announced on Tuesday, includes fixes for four critical vulnerabilities.
Critical Security Flaws Addressed
Among the critical issues resolved in this update are use-after-free vulnerabilities affecting various Chrome components such as Chromecast, Browser, Navigation, and Track. These specific flaws are identified as CVE-2026-106382, CVE-2026-106197, CVE-2026-106358, and CVE-2026-106347.
Google discovered one of these critical issues internally, while the remaining three were reported by security researcher Xinyang Ge. Utilizing artificial intelligence, Ge identified two of the vulnerabilities. Details regarding the bug bounties awarded are yet to be disclosed by Google.
High-Severity Vulnerabilities and External Contributions
In addition to the critical fixes, the update also addresses 53 high-severity vulnerabilities. Notably, 34 of these were reported by external security researchers. Xinyang Ge contributed to identifying approximately a dozen of these high-severity issues, many through AI-driven methods. However, not all discoveries by Ge are eligible for reward.
The 190 remaining vulnerabilities are classified as medium- to low-severity. Google itself discovered the majority of these issues, ensuring a broad scope of security improvements.
Bug Bounty Rewards and Vulnerability Breakdown
External researchers reported 62 of the vulnerabilities patched in the Chrome 155 update, with Google awarding approximately $33,000 in bug bounties. However, the specific amounts for nearly 50 reports remain undisclosed.
Frequent vulnerability types in this update include incorrect authorization (41 instances), use-after-free (34 instances), missing authorization (34 instances), UI misrepresentation (20 instances), information leak (17 instances), uninitialized resource (16 instances), confused deputy (9 instances), and improper input validation (9 instances).
Importantly, Google has confirmed that none of these vulnerabilities have been exploited in the wild, highlighting the proactive nature of this update.
The Chrome 155 update is currently being rolled out to users with version 155.0.8059.39/.40 available for Windows and macOS, and version 155.0.8059.39 for Linux.
